High‑Severity (CVSS 7.8) Zero‑Day Vulnerability Disclosed in Foxit PDF Software (ZDI‑CAN‑33991)
What Happened – The Zero Day Initiative (ZDI) has published an upcoming advisory (ZDI‑CAN‑33991) for Foxit PDF software with a CVSS 7.8 rating. The vendor has been notified and is developing a patch; TrendAI’s security filters already block exploitation for its customers.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a continuous vulnerability‑management program that surfaces newly‑disclosed flaws before they are publicly exploitable.
- Provides a concrete test of the control objective “Maintain up‑to‑date patching and evidence of remediation” that maps to NIST CSF 2.0 (Protect function).
- Highlights the value of a control‑mapping capability that can automatically collect remediation evidence and feed it into audit‑readiness dashboards.
Who Is Affected – Organizations that deploy Foxit PDF Reader/Editor across desktops, SaaS portals, or embedded PDF workflows (primarily technology, professional services, and government agencies).
Recommended Actions
- Verify that your asset inventory includes all Foxit installations.
- Initiate a temporary mitigation (e.g., restrict network access, apply vendor‑provided mitigations) while awaiting the official patch.
- Capture remediation steps in your continuous control‑assurance platform to demonstrate due‑diligence during audits.
Technical Notes – The advisory does not yet disclose the specific vulnerability type (e.g., memory corruption, privilege escalation) or CVE identifier; it is listed as “upcoming” with a CVSS 7.8 score. TrendAI’s pre‑emptive filters protect customers until the vendor releases a fix. Source: ZDI Upcoming Advisories